A flow playback method, system and device

The lost packets are uploaded through the page and played back using the Suricata command, which solves the problem of in-depth backend and low playback efficiency in the existing technology, and realizes efficient and secure packet playback.

CN113890757BActive Publication Date: 2025-05-23HANGZHOU ANHENG INFORMATION SECURITY TECH CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202111130185.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-09-26
Publication Date
2025-05-23
Estimated Expiration
2041-09-26

AI Technical Summary

Technical Problem

When the prior art plays back lost data packets in the database, it needs to enter the background, which reduces the security of the background and is inefficient in playback. It may still cause packet loss due to network bandwidth and other reasons.

Method used

By receiving lost packets uploaded by the user through the page and reading these packets based on the preset Suricata command, it can achieve efficient playback without entering the background.

Benefits of technology

It improves the security of the background, improves the playback efficiency, and avoids packet loss problems caused by network bandwidth and other reasons.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN113890757B_ABST
    Figure CN113890757B_ABST
Patent Text Reader

Abstract

The present invention discloses a traffic playback method, system and device, which first receive lost data packets uploaded by a user through a page, then read the lost data packets based on a preset Suricata command to play back the read lost data packets, and because the lost data packets are received in a page upload manner, there is no need to enter the background, which reduces the permissions that need to be opened in the background and improves the security of the background. In addition, the lost data packets are read based on the preset Suricata command to play back the lost data packets, and the playback efficiency is high, and packet loss due to network bandwidth and other reasons will not occur.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of security detection, and in particular to a traffic playback method, system and device. Background Art

[0002] When using security detection tools to perform security detection on data in a database, data is transmitted to the detection application in the form of data packets, and packet loss may occur due to various problems. For example, packet loss may occur due to poor network conditions, the security detection tool does not support the application protocol of the data packet, or the current database causes the inability to capture the lost data packet. Therefore, it is necessary to replay the lost data packet so that the application developer can find the cause of the packet loss. When replaying the lost data packet, the prior art needs to enter the background, then upload the data packet through the background, and then use the tcpreplay command to replay the lost data packet. On the one hand, the lost data packet needs to enter the background when replaying, which reduces the security of the background; on the other hand, the playback efficiency is low, and packet loss may still occur due to network bandwidth and other reasons. Summary of the invention

[0003] The purpose of the present invention is to provide a traffic playback method, system and device. It does not require access to the background, reduces the permissions that need to be opened, improves the security of the background, has high playback efficiency, and will not lose packets due to network bandwidth and other reasons.

[0004] In order to solve the above technical problems, the present invention provides a traffic playback method, comprising:

[0005] Receive lost data packets uploaded by users through the page;

[0006] The lost data packets are read based on a preset Suricata command to play back the read lost data packets.

[0007] Preferably, before receiving the lost data packet uploaded by the user, the method further includes:

[0008] The lost packets are determined.

[0009] Preferably, determining the lost data packet comprises:

[0010] Obtain the alarm results generated by multiple security detection tools based on the captured data packets when capturing data packets in the same data stream;

[0011] Determine, according to the alarm result, whether there is a data packet that is only alarmed by some of the security detection tools;

[0012] If so, it is determined that the data packet that is only alerted by part of the security detection tool is the lost data packet.

[0013] Preferably, after reading the lost data packet based on a preset Suricata command to replay the read lost data packet, the method further comprises:

[0014] Adding numbers corresponding to each of the lost data packets to the lost data packets;

[0015] The lost data packets are stored with numbers added.

[0016] Preferably, storing the numbered lost data packets comprises:

[0017] The file name, upload time and operation of the lost data packet after adding the number are stored, and the operation includes viewing the packet content.

[0018] Preferably, the number is a UUID.

[0019] Preferably, after storing the lost data packet, the method further comprises:

[0020] According to a preset alarm rule library, the lost data packet is matched with an alarm rule;

[0021] According to the alarm result matched by the alarm rule, a threat label corresponding to the alarm result matched by the alarm rule is marked on the lost data packet, wherein the threat label includes the threat name, alarm time, threat level, application protocol, threat type, source IP and destination IP of the lost data packet;

[0022] The threat tag is stored.

[0023] Preferably, it also includes:

[0024] According to the one-to-one corresponding numbers of the lost data packets input by the user, the threat labels of the lost data packets corresponding to the one-to-one corresponding numbers of the lost data packets input by the user are output.

[0025] The present invention also provides a traffic playback system, comprising:

[0026] A lost data packet receiving unit, used to receive lost data packets uploaded by users through a page;

[0027] The lost data packet reading unit is used to read the lost data packet based on a preset Suricata command to play back the read lost data packet.

[0028] The present invention also provides a traffic playback device, comprising:

[0029] Memory for storing computer programs;

[0030] A processor is used to implement the steps of the traffic playback method as described above when executing the computer program.

[0031] The present invention provides a traffic playback method, system and device, which first receive the lost data packets uploaded by the user through a page, then read the lost data packets based on a preset Suricata command to play back the read lost data packets, and because the lost data packets are received in a page upload manner, there is no need to enter the background, which reduces the permissions that need to be opened and improves the security of the background. In addition, the lost data packets are read based on the preset Suricata command to play back the lost data packets, and the playback efficiency is high, and packet loss due to network bandwidth and other reasons will not occur. BRIEF DESCRIPTION OF THE DRAWINGS

[0032] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the prior art and the drawings required for use in the embodiments are briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work.

[0033] Figure 1 A flow chart of a traffic playback method provided by the present invention;

[0034] Figure 2 This is a schematic diagram of the lost data packets uploaded by the user through the page;

[0035] Figure 3 A schematic diagram of reading lost packets based on Suricata commands;

[0036] Figure 4 A schematic diagram of an alarm result of matching an alarm rule for the lost data packet;

[0037] Figure 5 A schematic diagram of querying the threat label of a lost data packet based on UUID;

[0038] Figure 6 A schematic diagram of the structure of a traffic playback system provided by the present invention;

[0039] Figure 7 A schematic diagram of the structure of a traffic playback device provided by the present invention. DETAILED DESCRIPTION

[0040] The core of the present invention is to provide a traffic playback method, system and device. It does not require access to the backend, reduces the permissions that need to be opened, improves the security of the backend, has high playback efficiency, and will not cause packet loss due to network bandwidth and other reasons.

[0041] In order to make the purpose, technical solution and advantages of the embodiments of the present invention clearer, the technical solution in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.

[0042] Please refer to Figure 1 , Figure 1 A flow chart of a traffic playback method provided by the present invention.

[0043] The traffic playback method includes:

[0044] S11: receiving the lost data packet uploaded by the user through the page;

[0045] S12: Read the lost data packets based on the preset Suricata command to replay the read lost data packets.

[0046] Please refer to Figure 2 , Figure 2 Schematic diagram of lost data packets uploaded by users through the page.

[0047] Considering that the traditional traffic playback method requires entering the background to upload lost data packets, which is risky, based on the above problem, in this embodiment, a page upload method is adopted to receive lost data packets uploaded by users through the page, without entering the background, thereby reducing the danger caused by entering the background.

[0048] Please refer to Figure 3 , Figure 3 Schematic diagram of reading lost packets based on Suricata commands.

[0049] In addition, when manually inputting the tcpreplay command to replay the lost data packets, packet loss may still occur due to problems such as network bandwidth. Therefore, in this embodiment, the lost data packets are read based on the preset Suricata command to replay the lost data packets. Due to the Suricata command reading method adopted, packet loss due to reasons such as network bandwidth will not occur.

[0050] Specifically, when the lost data packet is read through the Suricata command, the Suricata command is: Suricata (engine name); -c configuration file; -r (uuid_original data packet name); --runmode single; -l log output path.

[0051] In summary, in this embodiment, the lost data packets uploaded by the user through the page are first received, and then the lost data packets are read based on the preset Suricata command to play back the lost data packets, without entering the background, thereby improving security, and using the Suricata command to read the packets for playback, there will be no packet loss due to network bandwidth and other reasons, thereby improving playback efficiency.

[0052] Based on the above embodiments:

[0053] As a preferred embodiment, before receiving the lost data packet uploaded by the user, the method further includes:

[0054] Identify lost packets.

[0055] Considering that the traditional packet playback method, when obtaining lost data packets, is usually performed by a technician on site to find lost data packets and then replay the lost data packets, the lost data packets cannot be automatically determined and are prone to missing lost data packets. Based on the above problems, in this embodiment, before receiving the lost data packets uploaded by the user, the system will also automatically determine the lost data packets, thereby realizing automatic determination of lost data packets and not easily missing lost data packets.

[0056] As a preferred embodiment, determining the lost data packet includes:

[0057] Obtain the alarm results generated by multiple security detection tools based on the captured data packets when capturing data packets in the same data stream;

[0058] Based on the alarm results, determine whether there are data packets that are only reported by some security detection tools;

[0059] If so, the data packets that are only alerted by some security detection tools are determined to be lost data packets.

[0060] In this embodiment, the lost data packet is determined by comparing the alarm results of multiple security detection tools.

[0061] Specifically, when using multiple security detection tools to perform security detection on the same data stream, a certain dangerous data packet may be captured by some security detection tools, thereby generating an alarm. For other security detection tools, poor network conditions or failure to support the application protocol of the dangerous data packet may result in failure to capture the data packet, resulting in loss of the dangerous data packet. Therefore, in this embodiment, first, the alarm results generated by multiple security detection tools based on the captured data packets when capturing data packets in the same data stream are obtained, and according to the alarm results, it is determined whether there are data packets that are only alarmed by some security detection tools. If there are data packets that are only alarmed by some security detection tools, it means that the data packet is dangerous and some security detection tools failed to capture the data packet. Therefore, the data packet that is only alarmed by some security detection tools is determined to be a lost data packet.

[0062] In summary, this embodiment determines lost data packets by comparing the alarm results of multiple security detection tools, thereby realizing automatic determination of lost data packets, and the implementation method is simple.

[0063] As a preferred embodiment, after reading the lost data packets based on the preset Suricata command to replay the read lost data packets, the method further includes:

[0064] Add numbers corresponding to each lost data packet to the lost data packets;

[0065] Store lost packets with numbers added.

[0066] Taking into account the traditional traffic playback method, when querying the replayed lost data packets, it is necessary to know in advance the search conditions such as the source IP, target IP and time range of the lost data packets, which makes it difficult to accurately search for the lost data packets. Based on the above problems, in this embodiment, the lost data packets are read based on the preset Suricata command to replay the read lost data packets. The system will add numbers corresponding to each lost data packet to the lost data packets, and store the lost data packets with added numbers, so that when the technician locates the lost data packets, he can accurately locate the only data packet according to the numbers corresponding to each lost data packet, thereby improving the efficiency and accuracy of positioning.

[0067] As a preferred embodiment, storing the lost data packets after adding numbers includes:

[0068] The file name, upload time and operation of the lost data packet after adding the number, including viewing the packet content.

[0069] In order to restore or trace back the lost data packet, in this embodiment, the system will store the file name, upload time and packet content of the lost data packet after adding a number, wherein the packet content includes SIP (Source Internet Protocol), that is, the source IP, which is used to determine the initiator of the lost data packet, and the destination IP (Internet Protocol), which is used to determine the receiver of the lost data packet, so that the technician can restore or trace back the lost data packet according to the file name, upload time and operation of the lost data packet.

[0070] As a preferred embodiment, the number is UUID (Universally Unique Identifier).

[0071] In this embodiment, the lost data packets are numbered by adding UUIDs corresponding to each lost data packet. UUID is a software-constructed standard that allows all elements in the system to have unique identification information without the need for a central control terminal to specify the identification information.

[0072] As a preferred embodiment, after storing the lost data packets, the method further comprises:

[0073] According to the preset alarm rule library, the lost data packets are matched with alarm rules;

[0074] According to the alarm result matched by the alarm rule, the lost data packet is marked with a threat label corresponding to the alarm result matched by the alarm rule. The threat label includes the threat name, alarm time, threat level, application protocol, threat type, source IP and destination IP of the lost data packet;

[0075] Stores threat tags.

[0076] Please refer to Figure 4 , Figure 4 A schematic diagram of the alarm result of matching the alarm rules for lost data packets.

[0077] In order to determine the alarm information of the lost data packet, in this embodiment, a preset alarm rule library is set. After the lost data packet is stored, the alarm rule matching is performed on the lost data packet according to the preset alarm rule library. For example, the alarm rule matching is performed on the lost data packet by detecting whether the lost data packet contains a dangerous field and matching the threat type and threat level corresponding to the dangerous field. For example, for the rule whose rule name is to detect icmp tunnel communication, the detection method is to generate an alarm when the ipconfig command is detected in the icmp protocol detection content. According to the alarm result matched by the alarm rule, the lost data packet is marked with a threat label corresponding to the alarm result matched by the alarm rule. The threat label contains the threat name, alarm time, threat level, application protocol, threat type, source IP and destination IP of the lost data packet, so that the technician can perform the next operation on the lost data packet according to the threat label, such as deleting or modifying the lost data packet.

[0078] As a preferred embodiment, it also includes:

[0079] According to the one-to-one corresponding numbers of the lost data packets input by the user, the threat labels of the lost data packets corresponding to the one-to-one corresponding numbers of the lost data packets input by the user are output.

[0080] Considering that after replaying the lost data packets and matching the lost data packets with alarm rules, the technicians have the need to view the specific alarm information of the lost data packets, therefore, the present embodiment provides a query function.

[0081] Specifically, according to the number corresponding to each lost data packet input by the user, the alarm time, threat level, threat type, source IP and destination IP of the lost data packet corresponding to the number are output for the technical staff to view. The number corresponding to each lost data packet here can be but not limited to UUID, please refer to Figure 5 , Figure 5 Schematic diagram of querying the threat label of lost data packets based on UUID.

[0082] Please refer to Figure 6 , Figure 6 A schematic diagram of the structure of a traffic playback system provided by the present invention.

[0083] The present invention also provides a traffic playback system, comprising:

[0084] The lost data packet receiving unit 61 is used to receive the lost data packets uploaded by the user through the page;

[0085] The lost data packet reading unit 62 is used to read the lost data packets based on a preset Suricata command to play back the read lost data packets.

[0086] For the relevant introduction of the traffic playback system, please refer to the above embodiments, and this application will not go into details here.

[0087] Please refer to Figure 7 , Figure 7 A schematic diagram of the structure of a traffic playback device provided by the present invention.

[0088] The present invention also provides a traffic playback device, comprising:

[0089] A memory 71, used for storing computer programs;

[0090] The processor 72 is used to implement the steps of the above-mentioned traffic playback method when executing the computer program.

[0091] For the relevant introduction of the traffic playback device, please refer to the above embodiment, and this application will not go into details here.

[0092] It should be noted that, in this specification, relational terms such as first and second, etc. are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Moreover, the terms "comprise", "include" or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. In the absence of further restrictions, an element defined by the statement "comprises a ..." does not exclude the presence of other identical elements in the process, method, article or device including the element.

[0093] The above description of the disclosed embodiments enables those skilled in the art to implement or use the present invention. Various modifications to these embodiments will be apparent to those skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of the present invention. Therefore, the present invention will not be limited to the embodiments shown herein, but rather to the widest scope consistent with the principles and novel features disclosed herein.

Claims

1. A traffic playback method, It is characterized in that include: Receive lost data packets uploaded by users through the page; Reading the lost data packets based on a preset Suricata command to replay the read lost data packets; Before receiving the lost data packet uploaded by the user, the following is also included: Obtain the alarm results generated by multiple security detection tools based on the captured data packets when capturing data packets in the same data stream; Determine, according to the alarm result, whether there is a data packet that is only alarmed by some of the security detection tools; If so, it is determined that the data packet that is only alerted by part of the security detection tool is the lost data packet.

2. The traffic playback method according to claim 1, It is characterized in that After reading the lost data packet based on a preset Suricata command to replay the read lost data packet, the method further includes: Adding numbers corresponding to each of the lost data packets to the lost data packets; The lost data packets are stored with numbers added.

3. The traffic playback method according to claim 2, It is characterized in that Storing the lost data packets after adding numbers, including: The file name, upload time and operation of the lost data packet after adding the number are stored, and the operation includes viewing the packet content.

4. The traffic playback method according to claim 2, It is characterized in that The number is a UUID.

5. The traffic playback method according to claim 2, It is characterized in that After storing the lost data packet, the method further comprises: According to a preset alarm rule library, the lost data packet is matched with an alarm rule; According to the alarm result matched by the alarm rule, a threat label corresponding to the alarm result matched by the alarm rule is marked on the lost data packet, wherein the threat label includes the threat name, alarm time, threat level, application protocol, threat type, source IP and destination IP of the lost data packet; The threat tag is stored.

6. The traffic playback method according to claim 5, It is characterized in that Also includes: According to the one-to-one corresponding numbers of the lost data packets input by the user, the threat labels of the lost data packets corresponding to the one-to-one corresponding numbers of the lost data packets input by the user are output.

7. A traffic playback system, It is characterized in that include: A lost data packet receiving unit, used to receive lost data packets uploaded by users through a page; A lost data packet reading unit, configured to read the lost data packet based on a preset Suricata command, so as to replay the read lost data packet; Among them, the traffic replay system is also used to obtain the alarm results generated by multiple security detection tools based on the captured data packets when capturing data packets in the same data stream; according to the alarm results, it is determined whether there are data packets that are only alarmed by some of the security detection tools; if so, the data packets that are only alarmed by some of the security detection tools are determined to be the lost data packets.

8. A traffic playback device, It is characterized in that include: Memory for storing computer programs; A processor, configured to implement the steps of the traffic playback method as described in any one of claims 1 to 6 when executing the computer program.

Citation Information

Patent Citations

  • Mobile terminal and data uploading method thereof

    CN101415151A